Key Takeaways
- In 2023, the US healthcare sector experienced 540 major data breaches reported to HHS, a 198% increase from 2022.
- From 2009 to 2023, HHS recorded 4,701 healthcare breaches affecting more than 319 million individuals.
- In Q1 2024 alone, 102 healthcare breach notifications were made, impacting 20.6 million records.
- Change Healthcare breach in Feb 2024 exposed records of up to 1/3 of Americans, estimated 100 million+ individuals.
- 2023 largest breach: Komodo Health, 58.5 million records exposed.
- From 2009-2023, total US healthcare breaches exposed 319,190,689 individuals per HHS.
- Healthcare data breaches in 2023 were 84% hacking-related per HHS.
- IBM 2023: Phishing responsible for 16% of healthcare breaches.
- Ransomware attacks made up 45% of healthcare breaches in 2023, per Sophos.
- IBM Cost of a Data Breach 2023: Average $10.93 million for healthcare, highest of all sectors.
- Healthcare breach costs rose 53% from 2020 to 2023, reaching $10.93M average.
- Ponemon 2023: Detection and escalation costs $1.76M average in healthcare breaches.
- Healthcare breaches increased 198% in 2023 vs 2022, HHS data.
- Data exposed doubled from 44M in 2022 to 112M in 2023.
- Ransomware in healthcare up 40% YoY through 2023.
Healthcare data breaches skyrocketed in 2023, hitting record highs for incidents and patients affected.
Breach Frequency and Counts
Breach Frequency and Counts Interpretation
Common Attack Vectors
Common Attack Vectors Interpretation
Economic and Financial Impacts
Economic and Financial Impacts Interpretation
Scale of Data Exposure
Scale of Data Exposure Interpretation
Temporal Trends and Forecasts
Temporal Trends and Forecasts Interpretation
Sources & References
- Reference 1HHShhs.govVisit source
- Reference 2OCRPORTALocrportal.hhs.govVisit source
- Reference 3HIPAAJOURNALhipaajournal.comVisit source
- Reference 4VERIZONverizon.comVisit source
- Reference 5SOPHOSsophos.comVisit source
- Reference 6BECKERSHOSPITALREVIEWbeckershospitalreview.comVisit source
- Reference 7CROWDSTRIKEcrowdstrike.comVisit source
- Reference 8PONEMONponemon.orgVisit source
- Reference 9OAGoag.ca.govVisit source
- Reference 10GOVgov.ukVisit source
- Reference 11OAICoaic.gov.auVisit source
- Reference 12EDPBedpb.europa.euVisit source
- Reference 13PRIVpriv.gc.caVisit source
- Reference 14IBMibm.comVisit source
- Reference 15NAAGnaag.orgVisit source
- Reference 16MANDIANTmandiant.comVisit source
- Reference 17BLACKBOOKMARKETRESEARCHblackbookmarketresearch.comVisit source
- Reference 18PHISHLABSphishlabs.comVisit source
- Reference 19CYBLEcyble.comVisit source
- Reference 20CMScms.govVisit source
- Reference 21IDTHEFTCENTERidtheftcenter.orgVisit source
- Reference 22ENISAenisa.europa.euVisit source
- Reference 23NHSENGLANDnhsengland.londonVisit source
- Reference 24STATISTAstatista.comVisit source
- Reference 25ICOico.org.ukVisit source






